CVE Vulnerabilities

CVE-2007-3511

Published: Jul 03, 2007 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the for attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 2.0.0.7 (including)
Firefox Mozilla 1.5.0.12 (including) 1.5.0.12 (including)
Firefox Mozilla 2.0.0.4 (including) 2.0.0.4 (including)
Firefox Mozilla 2.0.0.5 (including) 2.0.0.5 (including)
Firefox Mozilla 2.0.0.6 (including) 2.0.0.6 (including)
Seamonkey Mozilla * 1.1.4 (including)
Seamonkey Mozilla 1.0 (including) 1.0 (including)
Seamonkey Mozilla 1.0-alpha (including) 1.0-alpha (including)
Seamonkey Mozilla 1.0-beta (including) 1.0-beta (including)
Seamonkey Mozilla 1.0.1 (including) 1.0.1 (including)
Seamonkey Mozilla 1.0.2 (including) 1.0.2 (including)
Seamonkey Mozilla 1.0.3 (including) 1.0.3 (including)
Seamonkey Mozilla 1.0.4 (including) 1.0.4 (including)
Seamonkey Mozilla 1.0.5 (including) 1.0.5 (including)
Seamonkey Mozilla 1.0.6 (including) 1.0.6 (including)
Seamonkey Mozilla 1.0.7 (including) 1.0.7 (including)
Seamonkey Mozilla 1.0.8 (including) 1.0.8 (including)
Seamonkey Mozilla 1.0.9 (including) 1.0.9 (including)
Seamonkey Mozilla 1.0.99 (including) 1.0.99 (including)
Seamonkey Mozilla 1.1 (including) 1.1 (including)
Seamonkey Mozilla 1.1.1 (including) 1.1.1 (including)
Seamonkey Mozilla 1.1.2 (including) 1.1.2 (including)
Seamonkey Mozilla 1.1.3 (including) 1.1.3 (including)
Firefox Ubuntu dapper *
Firefox Ubuntu edgy *
Firefox Ubuntu feisty *
Firefox Ubuntu gutsy *
Firefox Ubuntu upstream *
Mozilla-thunderbird Ubuntu dapper *
Mozilla-thunderbird Ubuntu edgy *
Mozilla-thunderbird Ubuntu feisty *
Thunderbird Ubuntu gutsy *
Thunderbird Ubuntu upstream *
Red Hat Enterprise Linux 2.1 RedHat seamonkey-0:1.0.9-0.6.el2 *
Red Hat Enterprise Linux 3 RedHat seamonkey-0:1.0.9-0.5.el3 *
Red Hat Enterprise Linux 4 RedHat firefox-0:1.5.0.12-0.7.el4 *
Red Hat Enterprise Linux 4 RedHat seamonkey-0:1.0.9-6.el4 *
Red Hat Enterprise Linux 4 RedHat thunderbird-0:1.5.0.12-0.5.el4 *
Red Hat Enterprise Linux 5 RedHat firefox-0:1.5.0.12-6.el5 *
Red Hat Enterprise Linux 5 RedHat thunderbird-0:1.5.0.12-5.el5 *

References